Polityka Prywatności
Terms
Deepwater Digital Sp. z o. o.
44-100 Gliwice, Bojkowska 35A, Poland
Registered in the entrepreneurs register kept by the District Court Gliwice, 10th Commercial Division of the National Court Register, under KRS number: 0001105290, tax identification number: NIP 6312722410, REGON: 528634010
Privacy Policy
Effective date: 27.07.2026
Version: 2.2
This Policy sets out the rules for processing the personal data of Users of the deepwaterdigital.pl website, as well as the rules for storing information on, and accessing information stored on, Users’ terminal equipment (cookies and similar technologies).
Language. This document is a translation provided for convenience. The Polish-language version of the Policy is the binding version. In the event of any discrepancy between the two language versions, the Polish version prevails.
§1 Data Controller
The controller of personal data is Deepwater Digital Sp. z o.o., a Polish limited liability company with its registered office in Gliwice, ul. Chorzowska 50, 44-100 Gliwice, Poland.
Company registration details:
- Tax identification number (NIP): 6312722410
- National Court Register number (KRS): 0001105290
- Registry court: District Court in Gliwice, 10th Commercial Division of the National Court Register
Contact details:
- e-mail: [email protected]
- telephone: +48 732 498 561
We provide the above information also in fulfilment of the obligation arising from Article 206 §1 of the Polish Commercial Companies Code and Article 5 of the Polish Act on Providing Services by Electronic Means.
§2 Data Protection Officer
The Controller has appointed a Data Protection Officer, Filip Oliveira.
The Officer may be contacted on any matter concerning the processing of personal data and the exercise of rights under the GDPR:
- e-mail: [email protected]
- telephone: +48 732 498 561
- by post: ul. Chorzowska 50, 44-100 Gliwice, Poland, marked “IOD”
We publish the Officer’s details in fulfilment of Article 11 of the Polish Personal Data Protection Act of 10 May 2018.
§3 Definitions
Website (Serwis) – the website operating at www.deepwaterdigital.pl
User (Użytkownik) – a natural person using the Website
Terminal Equipment (Urządzenie końcowe) – an electronic device together with its software, by means of which the User accesses the Website
Cookies – computer data, in particular text files, stored on the User’s Terminal Equipment and capable of being read subsequently
GDPR (RODO) – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC
PKE – the Polish Act of 12 July 2024, Electronic Communications Law (Journal of Laws 2024, item 1221)
Personal data – information relating to an identified or identifiable natural person, including online identifiers such as cookie identifiers or IP addresses
Processing – an operation or set of operations performed on personal data, such as collection, recording, storage, alteration, consultation, use, disclosure, erasure or destruction
Profiling – any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person
Consent – a freely given, specific, informed and unambiguous indication of the User’s wishes by which the User, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to them
Consent management tool (Narzędzie zarządzania zgodami) – the mechanism installed on the Website by which the User grants, refuses or withdraws consent to individual categories of cookies. For this purpose the Controller uses the open-source library Cookie Consent v3 by Orest Bida, run locally on the Website
PUODO – the President of the Personal Data Protection Office, the Polish supervisory authority
§4 Legal basis for the use of cookies and rules for granting consent
The use of cookies other than strictly necessary ones requires the User’s prior consent. The legal basis is Article 399(1) PKE in conjunction with Article 6(1)(a) GDPR. Pursuant to Article 400 PKE, the provisions on the protection of personal data apply accordingly to obtaining the consent referred to in Article 399(1)(2) PKE, which means that consent must meet the requirements of Article 4(11) and Article 7 GDPR.
Cookies necessary to provide the service requested by the User, including files ensuring the security and correct operation of the Website and the file storing the User’s choices made in the consent management tool, are used without consent, on the basis of Article 399(3)(2) PKE and Article 6(1)(f) GDPR.
Consent is collected by means of the Cookie Consent v3 tool, displayed on the first visit to the Website.
The behaviour of analytics scripts prior to consent differs depending on the requirements of the individual providers:
a) Google Analytics 4. The measurement script is not executed until consent is granted. It is blocked in the Website’s code and loaded only after a consent signal is received. Until consent is granted, Google Analytics 4 does not store any information on the Terminal Equipment and does not send any data to Google.
b) Microsoft Clarity. In accordance with Microsoft’s requirements, the Clarity script is loaded on the page regardless of the User’s decision, so that it is able to receive a signal of consent or refusal. Until consent is granted, the script remains in a restricted mode: it does not store cookies, does not record session recordings and does not feed heatmaps. In this mode, only limited technical data may be processed which does not allow the User to be singled out or recognised across sessions. Full data collection begins only after a consent signal is passed to Clarity.
Refusing consent is as easy as granting it. The refusal button is visible on the first layer of the interface, next to the acceptance button, and carries the same visual weight.
Consent is given separately for each category of cookies. The User may accept one category and reject another using the preferences panel.
The User may withdraw consent at any time via the “Cookie settings” link available in the Website footer, which reopens the preferences panel. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. Following withdrawal, the Controller passes a refusal signal to Google and Microsoft, and the cookies covered by the withdrawn consent cease to be used.
A record of the User’s decision is stored locally on their Terminal Equipment in the cc_cookie file. Independently of this, the Controller maintains a consent register on its own side, covering the date and time of the decision, the scope of the categories granted and rejected, the version of the banner text and a technical event identifier, without storing the IP address in plain form. The register serves solely to demonstrate accountability in accordance with Article 5(2) and Article 7(1) GDPR.
The absence of consent does not restrict access to the content of the Website. It may, however, affect the operation of certain convenience features.
Independently of the above, the User may manage cookies directly in their web browser settings, including deleting them. Changing browser settings does not, however, replace consent given in the consent management tool.
§5 Categories and list of cookies
5.1 Strictly necessary cookies (used without consent)
cc_cookie – provider: the Website (Cookie Consent v3 library, run locally). Purpose: storing the User’s decisions regarding individual cookie categories and enabling the fact that consent was given to be demonstrated. Storage period: 182 days from the last update of preferences.
5.2 Analytics cookies (require consent)
Cookies set by Google in connection with the Google Analytics 4 service:
- _ga – distinguishing users; storage period up to 2 years
Cookies set by Microsoft in connection with the Microsoft Clarity service:
- _clck – associating page views with a Clarity user identifier; storage period 1 year
- _clsk – combining successive page views within a single session into one recording; storage period 1 day
- CLID – identifying the user within the Clarity project; storage period 1 year
5.3 Microsoft identification and advertising cookies (not used)
In certain configurations, Microsoft Clarity may use cookies set on Microsoft and Bing domains which are not purely analytical in nature but serve to identify the browser within Microsoft services and for advertising purposes:
- MUID – identifying the browser within Microsoft services; storage period up to 13 months
- ANONCHK – indicating whether the identifier is used for analytics purposes; storage period 10 minutes
- SM – synchronising the identifier across Microsoft domains; storage period: session
The Controller does not use these files. The Website does not carry out advertising activities using Microsoft tools, and accordingly the consent signal for advertising storage (ad_Storage in the Clarity Consent API) is permanently set to “denied”, regardless of the User’s decision in the consent management tool. The list above is provided for information only, so that the User can identify these files should they encounter them in their browser as a result of using other websites.
§6 Purposes of processing, legal bases and scope of data
6.1 Handling enquiries addressed to the Controller (contact form)
Scope of data: first name and surname, e-mail address, telephone number, message content.
Legal basis: Article 6(1)(b) GDPR where the enquiry is aimed at concluding a contract, or Article 6(1)(f) GDPR where the contact is of a different nature. The Controller’s legitimate interest in that case lies in being able to respond to the enquiry and in documenting correspondence.
Storage period: up to 3 years from the end of the correspondence, corresponding to the limitation period for claims connected with the conduct of business activity (Article 118 of the Polish Civil Code). If a longer limitation period applies in a given case, the storage period is extended accordingly.
6.2 Preparing and sending a commercial offer at the User’s request (quotation forms)
In addition to the general contact form, the Website provides dedicated quotation forms for individual services, for example a website pricing quotation form. These forms collect a broader range of information than the contact form, because they serve to prepare an individual offer.
Scope of data: first name and surname, e-mail address, telephone number, details of the business conducted or the entity represented (name, tax identification number, address, industry, size of organisation), the address of any existing website, information about the scope of the planned engagement, the expected budget and the delivery timeline, as well as any other information voluntarily provided by the User in the body of the form.
The data of a sole proprietor, including the business name, tax identification number and business address, constitute personal data within the meaning of the GDPR and are protected on the terms set out in this Policy. The registration data of companies are not personal data; however, the data of the person completing the form on behalf of such a company are.
Legal basis:
- Article 6(1)(b) GDPR, that is, steps taken at the request of the data subject prior to entering into a contract, where the form is completed by a natural person, including a sole proprietor;
- Article 6(1)(f) GDPR, where the form is completed by a person acting on behalf of another entity. The Controller’s legitimate interest in that case lies in being able to prepare and present an offer to the entity that requested it, and in documenting the course of the quotation process.
Nature of the offer sent. An offer prepared and sent in response to an enquiry submitted by the User through a quotation form constitutes a solicited commercial communication. Sending it does not require the separate consent referred to in Article 398(1) PKE, because it was the User who requested that it be presented and who indicated the contact channel. Separate, prior and freely given consent is, however, required for any further marketing contact not directly related to handling the specific enquiry, in particular sending a newsletter, offers of other services or commercial reminders after the quotation process has ended. The Controller does not infer such consent from the mere fact that a quotation form was completed.
Session recording. The fields of the quotation forms are masked in the Microsoft Clarity tool on the terms described in §7.2, so that the content entered by the User, including company details and budget information, is not captured in session recordings.
Storage period: up to 3 years from sending the offer or from the end of the correspondence concerning the enquiry, whichever occurs later, in accordance with the limitation period for claims connected with the conduct of business activity (Article 118 of the Polish Civil Code). Where a contract was concluded on the basis of the enquiry, data relating to its conclusion and performance are stored for the period arising from tax and accounting legislation, as indicated in §6.8.
6.3 Ensuring the security and correct operation of the Website (server logs)
The server hosting the Website automatically records the requests directed to it. This occurs regardless of the User’s decision in the consent management tool, because it is a technically inseparable element of delivering the page.
Scope of data: IP address, date and time of the request, address of the requested resource, server response code, volume of data transferred, information about the browser and operating system, referring page address.
Legal basis: Article 6(1)(f) GDPR. The Controller’s legitimate interest lies in ensuring the security of the Website, detecting abuse and faults, and ensuring continuity of operation.
Log data are not combined with data from the forms or with data from analytics tools and are not used to build a profile of the User.
Storage period: in accordance with §11.
6.4 Analytics and visit statistics (Google Analytics 4)
Scope of data: cookie identifier, approximate location, device, operating system and browser type, subpages visited, events recorded.
Legal basis: Article 6(1)(a) GDPR, that is, the User’s consent.
Storage period: in accordance with §11.
6.5 Analysis of on-site behaviour, heatmaps and session recordings (Microsoft Clarity)
Scope of data: cookie identifier, cursor movements, clicks, page scrolling, screen resolution, device and browser type, subpages visited.
Legal basis: Article 6(1)(a) GDPR, that is, the User’s consent. The consent also constitutes the basis for disclosing these data to Microsoft, which acts as a separate controller in relation to them (§7.2).
Storage period: in accordance with §11.
6.6 Establishment, exercise or defence of legal claims
Scope of data: data necessary to conduct the specific matter.
Legal basis: Article 6(1)(f) GDPR. The Controller’s legitimate interest lies in protection against claims and in the ability to pursue them.
Storage period: until the limitation period for claims expires.
6.7 Demonstrating the accountability of consents
Scope of data: the data indicated in §4(8).
Legal basis: Article 6(1)(c) GDPR in conjunction with Article 5(2) and Article 7(1) GDPR.
Storage period: in accordance with §11.
6.8 Fulfilment of other legal obligations incumbent on the Controller
Scope of data: data required by applicable legislation, in particular tax and accounting legislation.
Legal basis: Article 6(1)(c) GDPR.
Storage period: the period arising from the relevant legislation.
6.9 Voluntary nature of providing data
Providing data in the contact form and in the quotation forms is voluntary but necessary, respectively, in order to respond to the enquiry or to prepare an offer. Failure to provide data marked as mandatory will make it impossible to handle the enquiry. Fields not marked as mandatory, in particular those concerning budget, delivery timeline or details of the planned engagement, may be left blank by the User; omitting them may only affect the accuracy of the quotation prepared.
§7 Third-party analytics tools
Once consent has been obtained, the Controller uses the tools described below.
7.1 Google Analytics 4
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Role: processor, acting under a data processing agreement (the Google Ads Data Processing Terms, which cover the Google Analytics service) accepted by the Controller.
Purpose: compiling visit statistics, analysing traffic sources, measuring the effectiveness of published content.
Scope of data: cookie identifier, approximate location at city level, device type, operating system, browser, subpages visited, visit duration, events recorded.
IP address: Google Analytics 4 does not record or store the IP addresses of Users from the European Economic Area, the United Kingdom and Switzerland. The address is used only transiently, at the moment of collection, to determine the approximate location, and is then discarded before storage.
Consent signals: the Controller uses the Google Consent Mode v2 mechanism in its basic variant. This means that the ad_storage, analytics_storage, ad_user_data and ad_personalization signals default to “denied”, and the measurement tags themselves are not executed until the analytics_storage signal is changed to “granted” as a result of the User’s decision. Advertising-related signals remain set to “denied” regardless of the User’s decision, because the Controller does not carry out advertising activities within the Google ecosystem.
Disabled features: Google Signals and data sharing with other Google services remain disabled. The Controller does not use Google Analytics 360.
Storage period for user-level and event-level data: 14 months. This setting applies to granular data. Aggregated data in standard Google Analytics reports, which do not allow the User to be singled out, may remain available for longer.
Provider’s privacy policy: https://policies.google.com/privacy
Additional opt-out option: independently of the consent management tool, the User may install a browser add-on that blocks Google Analytics, available at https://tools.google.com/dlpage/gaoptout
7.2 Microsoft Clarity
Provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.
Role: in relation to the data collected by Clarity, Microsoft acts as a separate data controller, not as a processor acting solely on the Controller’s instructions. This means that Microsoft independently determines the purposes and means of processing part of these data, including that it may use them to develop and improve its own products and services, on the terms described in the Microsoft Privacy Statement. The Controller has no influence over that scope of processing and is not responsible for it.
Purpose: analysing how the Website is used, creating heatmaps, recording sessions, detecting interface errors.
Scope of data: cookie identifier, cursor movements, clicks, page scrolling, screen resolution, device and browser type, approximate location, subpages visited.
Masking: by default, Clarity masks the content of text fields and password fields. In addition, the Controller has applied a masking attribute to the fields of the contact form and of all quotation forms, so that the data entered in them, including company details and budget information, are not captured in session recordings.
Consent mechanism: Microsoft provides its own consent mechanism for Clarity (Clarity Consent API version 2), independent of Google Consent Mode v2, which does not support Clarity. That mechanism distinguishes two independent signals: analytics_Storage and ad_Storage. The Controller passes to Clarity only the analytics_Storage signal corresponding to the User’s decision; the ad_Storage signal remains permanently set to “denied”. The behaviour of the script prior to consent is described in §4(4)(b).
Storage period (on Microsoft’s side): playback data for session recordings 30 days; sessions labelled or marked as favourites 9 months; click data and heatmaps 9 months. After these periods, the data are deleted from Microsoft’s servers together with backups.
Provider’s privacy statement: https://privacy.microsoft.com/en-gb/privacystatement
7.3 Changes on the providers’ side
The terms of service, privacy policies, storage periods and scope of data processing of the entities indicated above may change independently of the Controller. The Controller monitors such changes and updates this Policy. The parameters cited in §5 and §7 reflect the position as at the effective date of this version of the Policy.
§8 Scope of data collected
8.1 Data collected regardless of consent
The data recorded in server logs, indicated in §6.3. They are collected in connection with the delivery of the page itself and do not depend on the decision made in the consent management tool.
8.2 Data collected automatically following consent
The data below constitute personal data within the meaning of the GDPR, because in combination with cookie identifiers they make it possible to single out the User indirectly:
- browser type and version
- screen resolution
- operating system and device type
- subpages of the Website visited
- interactions with interface elements
- time spent on individual subpages
- address of the previous subpage and referring page address
- browser language
- approximate location determined on the basis of the IP address
8.3 Data provided voluntarily
Through the contact form and other contact channels, the Controller collects first name and surname, e-mail address, telephone number and message content.
Through the dedicated quotation forms, the Controller additionally collects details of the business conducted or the entity represented (name, tax identification number, address, industry, size of organisation), the address of any existing website, and information about the scope of the planned engagement, the expected budget and the delivery timeline. A detailed description of this processing purpose is set out in §6.2.
The Controller does not knowingly collect special categories of data referred to in Article 9 GDPR. Please do not include such data in the content of your message.
§9 Recipients of personal data
Personal data may be disclosed to the following categories of recipients:
- cyber_Folks S.A. as the hosting services provider, under a data processing agreement. The infrastructure used to provide the service is located in Poland.
- Google Ireland Limited as the provider of the analytics tool, under a data processing agreement.
- Microsoft Ireland Operations Limited as the provider of the behaviour analysis tool, acting as a separate controller on the terms described in §7.2.
- Proton AG as the e-mail service provider, under a data processing agreement.
- cyber_Folks S.A as the provider of a CRM system, a form handling tool or a tool for preparing and sending offers, under a data processing agreement.
- Entities providing the Controller with legal, accounting or IT services, to the extent necessary to perform the services commissioned.
- Public authorities, to the extent and on the terms arising from applicable legislation.
The Cookie Consent v3 consent management tool does not constitute a separate recipient of data, because it operates solely in the User’s browser and does not transfer data to any external entity. The consent register referred to in §4(8) is maintained within the Controller’s infrastructure.
The Controller does not sell Users’ personal data.
§10 Transfers of data outside the European Economic Area
Data collected through the contact form, server log data and the consent register remain within the territory of Poland and are not transferred outside the EEA.
Data collected by Google Analytics 4 and Microsoft Clarity may be transferred to the United States and processed by Google LLC and Microsoft Corporation respectively.
The legal basis for these transfers is the European Commission implementing decision of 10 July 2023 finding an adequate level of protection of personal data under the EU-US Data Privacy Framework, to which certified entities from the Google and Microsoft groups are subject. Standard Contractual Clauses adopted by the European Commission are applied on a supplementary basis.
The Controller notes that the validity of that decision has been challenged before the courts of the European Union. By judgment of 3 September 2025 in Case T-553/23 (Latombe v Commission), the General Court of the European Union dismissed the action for annulment of the decision, confirming its validity. An appeal has been brought against that judgment and remains pending before the Court of Justice of the European Union under case number C-703/25 P. The Controller monitors the status of this mechanism and, in the event that the decision is invalidated, will promptly adapt the manner of processing and provide information about this in this Policy.
Copies of the transfer safeguards applied may be obtained by contacting the Data Protection Officer.
§11 Data storage periods
Data from the contact form are stored for up to 3 years from the end of the correspondence, on the terms described in §6.1.
Data from the quotation forms are stored for up to 3 years from sending the offer or from the end of the correspondence concerning the enquiry, whichever occurs later, on the terms described in §6.2. Where a contract was concluded, documentation relating to its conclusion and settlement is stored for the period arising from tax and accounting legislation.
Server logs are stored for 30 to 90 days and are then erased or anonymised.
Data covered by pending proceedings or a dispute are stored until the matter is finally concluded and the limitation period for claims has expired.
Google Analytics 4 data at user and event level are stored for 14 months.
In Microsoft Clarity, playback data for session recordings are stored for 30 days, sessions labelled or marked as favourites for 9 months, and click data and heatmaps for 9 months.
The record of consent given for cookies is stored on the User’s Terminal Equipment for 182 days from the last update of preferences. The consent register maintained by the Controller, referred to in §4(8), is stored for the duration of the consent and for 3 years after it expires or is withdrawn, in order to demonstrate accountability.
Aggregate statistics that do not allow the User to be identified may be stored indefinitely, solely in anonymised form.
Once the periods indicated have elapsed, the data are erased or irreversibly anonymised.
§12 Profiling and automated decision-making
Users are not subject to automated decisions producing legal effects concerning them or similarly significantly affecting them within the meaning of Article 22 GDPR.
The analytics tools described in §7 do, however, carry out automated analysis of Users’ behaviour on the Website, including grouping visits according to technical characteristics and manner of use. These activities may constitute profiling within the meaning of Article 4(4) GDPR. They take place solely on the basis of consent and serve exclusively statistical purposes and the improvement of the Website.
The User has the right to object to profiling on the terms described in §13 and, in respect of profiling based on consent, may withdraw that consent at any time.
§13 Users’ rights
In connection with the processing of personal data, the User has the following rights:
- Right of access to data (Article 15 GDPR), including the right to obtain a copy of the data.
- Right to rectification of inaccurate data and completion of incomplete data (Article 16 GDPR).
- Right to erasure (Article 17 GDPR).
- Right to restriction of processing (Article 18 GDPR).
- Right to data portability in a structured, commonly used, machine-readable format (Article 20 GDPR), in respect of data processed by automated means on the basis of consent or a contract.
- Right to object to processing based on legitimate interest, including to profiling (Article 21 GDPR).
- Right to withdraw consent at any time (Article 7(3) GDPR). Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal. Consent to cookies may be withdrawn in the “Cookie settings” panel available in the Website footer.
- Right to lodge a complaint with the supervisory authority, which is the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland, https://uodo.gov.pl
To exercise these rights, please contact the Data Protection Officer. The Controller responds without undue delay and in any event within one month of receiving the request. Where requests are complex or numerous, the period may be extended by a further two months, of which the User will be informed together with the reasons for the delay.
The Controller may refuse to comply with a request for erasure to the extent that processing is necessary for the establishment, exercise or defence of legal claims, or for compliance with a legal obligation. A refusal always states the legal basis and informs the User of the right to lodge a complaint with PUODO.
In relation to data processed by Microsoft as a separate controller (§7.2), the User may address requests directly to Microsoft, on the terms indicated in the Microsoft Privacy Statement. The Controller will provide assistance in this respect as far as possible.
§14 Data security
The Controller applies technical and organisational measures appropriate to the risk, as referred to in Article 32 GDPR, including TLS encryption of the connection, access control, backups and incident response procedures.
The Controller maintains a record of processing activities and a register of personal data breaches.
In the event of a personal data breach, the Controller notifies the President of the Personal Data Protection Office without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Article 33(1) GDPR). Where the breach is likely to result in a high risk to the rights and freedoms of Users, the Controller also notifies the data subjects.
The mechanisms for storing and reading cookies are implemented by built-in browser functions and do not allow other data to be retrieved from the Terminal Equipment or data from other websites visited.
The Controller notes that data security is also affected by the configuration and condition of the User’s Terminal Equipment, including whether software is up to date and free of malware. We recommend using current versions of browsers and operating systems.
§15 Contact
On matters concerning the protection of personal data, please contact the Data Protection Officer, whose details are given in §2.
On all other matters, the Controller may be contacted:
- by post: Deepwater Digital Sp. z o.o., ul. Chorzowska 50, 44-100 Gliwice, Poland
- by e-mail: [email protected]
- by telephone: +48 732 498 561
- via the contact form available at www.deepwaterdigital.pl/kontakt
§16 Technical requirements
Restricting the storage of and access to cookies may affect the operation of certain Website features, in particular features that remember the User’s preferences. Access to the content of the Website remains possible even where consent to cookies other than strictly necessary ones is refused.
§17 Links to external websites
The Website may contain links to the websites of third parties. The Controller has no influence over the content of those websites or over the data processing rules they apply. We encourage you to read the privacy policies in force on the websites to which you navigate.
§18 Changes to the Policy
The Controller may amend this Policy, in particular in connection with changes in legislation, in the tools used or in the scope of the services provided.
The Controller provides information about every amendment by publishing a new version of the Policy on the Website, indicating the effective date and version number.
In the case of amendments that materially affect the scope or purposes of the processing of personal data, the Controller will additionally inform those persons whose e-mail address it holds in connection with ongoing correspondence, at least 14 days before the amendments take effect. For other Users, information about the amendment is presented on the Website and, as regards cookies, also in the consent management tool.
Where an amendment concerns processing based on consent, the Controller will request new consent. Until such consent is obtained, processing within the new scope will not be carried out.
Previous versions of the Policy are archived and made available on request addressed to the Data Protection Officer.
§19 Legal basis of the Policy
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR)
- The Polish Act of 10 May 2018 on the Protection of Personal Data (Journal of Laws 2018, item 1000, as amended), in particular Articles 10 and 11
- The Polish Act of 12 July 2024, Electronic Communications Law (Journal of Laws 2024, item 1221), in particular Articles 398, 399 and 400
- The Polish Act of 18 July 2002 on Providing Services by Electronic Means (Journal of Laws 2002, No. 144, item 1204, as amended)
- The Polish Act of 15 September 2000, Commercial Companies Code (Journal of Laws 2000, No. 94, item 1037, as amended), Article 206
- The Polish Act of 23 April 1964, Civil Code (Journal of Laws 1964, No. 16, item 93, as amended), Article 118

Any other questions?
